Pingidentity

Pingfederate

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 14.09.2026 10:43:20
  • Zuletzt bearbeitet 18.09.2026 19:30:42

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.

  • EPSS 0.15%
  • Veröffentlicht 10.08.2026 21:54:21
  • Zuletzt bearbeitet 29.09.2026 11:10:00

Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.

  • EPSS 0.34%
  • Veröffentlicht 27.10.2025 14:39:41
  • Zuletzt bearbeitet 08.10.2026 11:10:00

Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.

  • EPSS 0.32%
  • Veröffentlicht 15.06.2025 15:25:38
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.

  • EPSS 0.29%
  • Veröffentlicht 15.06.2025 15:00:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.

  • EPSS 0.29%
  • Veröffentlicht 15.06.2025 14:25:39
  • Zuletzt bearbeitet 15.04.2026 00:35:42

PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.

  • EPSS 0.17%
  • Veröffentlicht 09.07.2024 23:15:10
  • Zuletzt bearbeitet 21.11.2024 08:56:21

A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.

  • EPSS 0.44%
  • Veröffentlicht 09.07.2024 23:15:10
  • Zuletzt bearbeitet 21.11.2024 08:56:09

The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.

  • EPSS 0.24%
  • Veröffentlicht 09.07.2024 23:15:10
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.

  • EPSS 0.46%
  • Veröffentlicht 10.04.2024 00:15:09
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests.